We have discovered 3,791,874 live websites that are affected by CWE-862.
![]() | 1,396,606 websites |
![]() | 422,702 websites |
![]() | 224,977 websites |
![]() | 158,035 websites |
![]() | 130,730 websites |
![]() | 108,926 websites |
![]() | 94,073 websites |
![]() | 90,587 websites |
![]() | 86,518 websites |
![]() | 85,743 websites |
.com | 1,658,060 websites |
.de | 197,752 websites |
.org | 172,696 websites |
.it | 123,922 websites |
.co.uk | 96,858 websites |
.nl | 94,367 websites |
.net | 91,899 websites |
.fr | 83,011 websites |
.com.br | 79,663 websites |
.pl | 74,129 websites |
Discovered | CVE | Description | Websites |
---|---|---|---|
May, 2025 | CVE-2025-3527 | EventON - WordPress Virtual Event Calendar Plugin <= 4.9.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting | 14,760 |
May, 2025 | CVE-2025-31063 | WordPress Wishlist <= 2.1.0 - Broken Access Control Vulnerability | 2 |
May, 2025 | CVE-2025-39482 | WordPress Eventer - WordPress Event & Booking Manager Plugin plugin <= 3.9.6 - Broken Access Control vulnerability | 85 |
May, 2025 | CVE-2025-47563 | WordPress CURCY plugin <= 2.3.7 - Arbitrary Shortcode Execution vulnerability | 1,613 |
May, 2025 | CVE-2025-47564 | WordPress EventON plugin <= 4.9.9 - Broken Access Control vulnerability | 14,760 |
May, 2025 | CVE-2025-48079 | WordPress ProfileGrid <= 5.9.5.1 - Broken Access Control Vulnerability | 793 |
May, 2025 | CVE-2025-48116 | WordPress EventON <= 2.4.4 - Broken Access Control Vulnerability | 3,130 |
May, 2025 | CVE-2025-48138 | WordPress BERTHA AI <= 1.12.11 - Broken Access Control Vulnerability | 17 |
May, 2025 | CVE-2025-4520 | Uncanny Automator <= 6.4.0.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update | 363 |
May, 2025 | CVE-2025-24021 | iTop doesn't have mass assignment of fields in the portal form | 16 |
Discovered | CVE | Description | Websites |
---|---|---|---|
Jun, 2024 | CVE-2024-34444 | WordPress Slider Revolution plugin < 6.7.0 - Unauthenticated Broken Access Control vulnerability | 1,252,119 |
Jun, 2024 | CVE-2023-33922 | WordPress Elementor plugin <= 3.13.2 - Broken Access Control vulnerability | 464,121 |
Jan, 2025 | CVE-2024-56276 | WordPress WPForms Lite plugin <= 1.9.2.2 - Broken Access Control vulnerability | 286,404 |
Jun, 2024 | CVE-2023-35050 | WordPress Elementor Pro plugin <= 3.13.0 - Auth. Broken Access Control vulnerability | 271,441 |
Jun, 2024 | CVE-2023-47788 | WordPress Jetpack plugin < 12.7 - Contributor+ Broken Access Control vulnerability | 259,965 |
Jan, 2025 | CVE-2025-24751 | WordPress CoBlocks plugin <= 3.1.13 - Broken Access Control vulnerability | 232,360 |
Apr, 2025 | CVE-2025-3953 | WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin <= 14.13.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Update | 129,434 |
Dec, 2024 | CVE-2024-11205 | WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation | 125,843 |
Jun, 2024 | CVE-2023-28775 | WordPress Yoast SEO Premium plugin <= 20.4 - Unauthenticated Zapier API Key Reset vulnerability | 121,076 |
Jun, 2024 | CVE-2023-39312 | WordPress Avada theme <= 7.11.1 - Auth. Unrestricted Zip Extraction vulnerability | 111,341 |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.com | ![]() | ** | |
**********.com | ![]() | *** | |
********.com | ![]() | *** | |
*****.net | ![]() | *** | |
****.******.com | ![]() | *** | |
*****.com | ![]() | *** | |
**************.de | ![]() | *** | |
*********.com | ![]() | *** | |
****.com | ![]() | *** | |
*******.org | ![]() | *** |